maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
https://launchpad.net/maas/+milestone/13.10
https://bugs.launchpad.net/maas/%2Bbug/1039513